Ibm
ibm
8,250 CVEs • 1,572 products
Products (1,572)
Click to collapseToggle
Products (1,572)
Click to collapse
CVEs (8,250)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 2Business Automation Workflow Business Process ManagerJun 17, 2026 Nov 5, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized intercepti...Show more |
1Ibm 1Infosphere Information Server Jun 17, 2026 Nov 2, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consum...Show more |
1Ibm 1Infosphere Information Server Jun 17, 2026 Nov 2, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force...Show more |
1Ibm 1Infosphere Information Server Jun 17, 2026 Nov 2, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information due to a insecure third party domain access vulnerability. IBM X-Force ID: 206572. |
1Ibm 1Infosphere Information Server Jun 17, 2026 Nov 2, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more |
1Ibm 1Infosphere Information Server Jun 17, 2026 Nov 2, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, pot...Show more |
1Ibm 1Infosphere Information Server Jun 17, 2026 Nov 2, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of the REST API server certificate. IBM X-Force ID: 201301. |
IBM i2 iBase 8.9.13 and 9.0.0 could allow a local attacker to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 206213. |
1Ibm 7Engineering Lifecycle Optimization Engineering Requirements Quality Assistant On PremisesEngineering Workflow Management+4 moreJun 17, 2026 Oct 27, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or fac...Show more |
1Ibm 6Engineering Lifecycle Optimization Engineering Workflow ManagementRational Collaborative Lifecycle Management+3 moreJun 17, 2026 Oct 27, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172. |
1Ibm 6Engineering Lifecycle Optimization Engineering Workflow ManagementRational Collaborative Lifecycle Management+3 moreJun 17, 2026 Oct 27, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025. |
1Ibm 5Engineering Lifecycle Optimization Rational Collaborative Lifecycle ManagementRational Doors Next Generation+2 moreJun 17, 2026 Oct 27, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to crede...Show more |
1Ibm 6Engineering Lifecycle Optimization Engineering Workflow ManagementRational Collaborative Lifecycle Management+3 moreJun 17, 2026 Oct 27, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to crede...Show more |
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information...Show more |
1Ibm 1Business Automation Workflow Jun 17, 2026 Oct 22, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality...Show more |
1Ibm 1Transformation Extender Advanced Jun 17, 2026 Oct 21, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 IBM Standards Processing Engine (IBM Transformation Extender Advanced 9.0 and 10.0) does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending...Show more |
1Ibm 10Flashsystem 9000 Firmware Flashsystem 9100 FirmwareSan Volume Controller Firmware+7 moreJun 17, 2026 Oct 21, 2021 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service due to a restricted shell escape vulnerability. IBM X-Force ID: 206229. |
IBM QRadar Advisor 2.5 through 2.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to...Show more |
1Ibm 1Security Risk Manager On Cp4s Jun 17, 2026 Oct 19, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 IBM Security Risk Manager on CP4S 1.7.0.0 stores user credentials in plain clear text which can be read by a an authenticatedl privileged user. IBM X-Force ID: 209940. |
1Ibm 1Security Risk Manager On Cp4s Jun 17, 2026 Oct 19, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Security Risk Manager on CP4S 1.7.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadi...Show more |